Fast, Honest, Affordable Service. That's Our Promise.

    CMMC 2.0  |  NIST SP 800-171  |  Central Connecticut

    Get Assessment-Ready for CMMC Before You Pay an Assessor.

    Small defense subcontractors in Connecticut are getting flow-down letters from their primes and have no idea where they stand. We do the readiness work: find the gaps, fix them, write the documents, and organize the evidence. Then you walk into a Level 2 assessment prepared instead of paying to fail it.

    Prepared for: Connecticut machine shops, fabricators, electronics and test firms, and other suppliers to Pratt & Whitney, Sikorsky, Electric Boat and their tier-1s.

    Where things stand right now

    Status: Phase 2 paused, requirements still in force
    Updated August 2026. We revise this section when the CMMC Reform Task Force publishes its recommendations.
    1. Nov 10, 2025In effect

      CMMC Phase 1 began. Level 1 and Level 2 self-assessments, with a score posted to SPRS, are required in new DoD contracts.

    2. Jul 13, 2026Paused

      The Department of War suspended Phase 2 (third-party Level 2 certification, scheduled for Nov 10, 2026) and opened a 60-day reform review.

    3. TodayStill required

      DFARS 252.204-7012 and NIST SP 800-171 apply to every contract that touches Controlled Unclassified Information. Your prime can ask for your SPRS score and your System Security Plan tomorrow.

    Why the pause is good news for you

    Getting a shop through a third-party Level 2 assessment with a large compliance firm routinely runs into six figures, and assessors bill for every hour, including the hours spent documenting what you got wrong. Nobody knows exactly when the certification requirement returns. What we do know is that the 110 controls will not disappear. Getting them in place now, at a small shop's pace and price, is the cheapest path there is.

    CMMC in plain English

    What it is

    CMMC is the Department of Defense’s way of checking that contractors actually follow the NIST SP 800-171 security rules they have been agreeing to since 2017. Level 1 covers 17 basic practices for Federal Contract Information. Level 2 covers all 110 controls of NIST SP 800-171 and applies to anyone who handles Controlled Unclassified Information (CUI): drawings, specs, test data, anything marked or flowed down from a DoD program.

    What a flow-down letter means

    When a prime sends you a letter asking for your SPRS score, your CMMC level, or a copy of your SSP, they are deciding whether you stay on the approved supplier list. A missing or low score is a reason to move the work to a shop that has one.

    What an SPRS score is

    You score yourself against the 110 controls, starting at 110 and subtracting points for each one you do not meet (some cost 1, some 3, some 5). Scores can go negative. You post that number to the Supplier Performance Risk System and certify it is accurate. A false score is a False Claims Act problem, so guessing is not a strategy.

    Where most small shops stand today

    Sound familiar? You are not alone. Every shop we assess starts with most of these. None of them are unusual. All of them are fixable.

    Everyone logs in as a local administrator, or with a shared “shop” account
    No multi-factor authentication on email, remote access, or the file server
    CUI drawings sitting in email, a personal Dropbox, or a USB stick on the CNC
    No central logging. If something happened last Tuesday, nobody can say what
    Windows 10 machines still on the floor, a year past end of support
    Antivirus on some computers, nobody sure which
    Backups exist, nobody has checked them in a while
    No written policies, no System Security Plan, no incident response plan
    Old accounts still active for employees who left two years ago
    35
    Typical first look
    About 35 of 110 controls met. SPRS scores well below zero are common.
    110
    Assessment-ready
    All 110 controls met, evidence on file for each one.

    Illustrative. Your starting score is whatever the truth is, and the first thing we do is find out.

    What we do: readiness, not certification

    We are not an assessor and we do not issue certificates. Our job is to make sure that when you do hire one, the assessment is a formality.

    Gap assessment and honest SPRS score

    We review all 110 controls against your actual environment, on site, and give you a real score with a written list of what is missing. Free written summary; you keep it either way.

    System Security Plan and POA&M

    The two documents every prime and every assessor asks for first. Written for your shop, in plain language, describing how you actually operate.

    Technical controls

    MFA everywhere it belongs. Managed endpoint protection on every machine. Centralized logging with retention. Access control that matches job roles. Patching that runs. Backups that are verified. Windows 10 retired.

    Policies and people

    Acceptable use policy signed by every employee, onboarding and offboarding procedures, phishing awareness through an online training platform, and one-on-one help for the owner on what the rules mean day to day.

    Evidence, organized

    Assessors want proof, not promises. We collect screenshots, configs, logs, and signed documents into an evidence package mapped to each control so nobody is digging through folders during the assessment.

    Keep it true

    Compliance drifts the week after you achieve it. Ongoing monitoring, monthly reporting, and a fixed point of contact keep the controls in place between assessments.

    Readiness first saves real money

    CMMC hardening at a large compliance firm is expensive. That is not a knock on them; it is the market. Enterprise-scale consultants, project managers, and hourly rates built for companies with a hundred seats. A 12-person shop pays the same rate card.

    Then the assessment itself. Connecticut firms that take shops through Level 2 certification quote well into six figures for the full project, and if you walk in with open findings you pay for the findings, pay to fix them, and then pay for the re-assessment.

    Straight talk about cost

    Every shop is different, so we quote after the gap assessment, in writing, before any work starts. What we can say up front: our rates are a fraction of what regional compliance firms charge, and there is no retainer. The money you save on readiness is money you still have when the assessor's invoice arrives.

    UnpreparedLarge firmCT Tech Express
    Who does the workYou, between jobsConsultant team, remoteOne technician, on site
    Rate structuren/aEnterprise hourly or retainerSmall-shop hourly, month to month, no retainer
    Result at assessmentOpen findings, re-assessmentReadyReady
    Assessor hours spent on your gapsManyFewFew
    Support after the assessmentNoneSeparate contractSame person, same rates

    What we don't do, and who does

    We do not

    • Issue CMMC certificates. Only a DoD-authorized C3PAO can.
    • Guarantee you will pass. We get you to the point where passing is the expected outcome, and we show you the evidence before you book the assessment.
    • Sell you a “compliance in a box” you do not understand. You will know what every control does and why.

    When you are ready

    • We work directly with a Connecticut managed IT firm that holds its own CMMC Level 2 certification, for shops that need a certified provider to take on part of their in-scope environment, and we can introduce you to a Connecticut C3PAO for the assessment itself.
    • We stay involved through the assessment: answering the assessor’s questions, pulling evidence, and fixing anything they flag.

    Case study: a central Connecticut test and engineering firm

    21
    endpoints monitored
    3-year
    tamper-evident log retention
    14
    signed acceptable use policies
    On-prem
    SIEM, data never leaves the building

    The situation

    About 20 endpoints and a small server rack. Engineering and test data covered by DFARS 7012 sitting on a shared file server. Handshake-level IT, no logging, no signed policies, and a prime starting to ask questions.

    What we put in place

    • Self-hosted SIEM on their own hardware, so security telemetry never leaves the building. Every workstation and server reporting.
    • File-level auditing on the CUI folders: every read, copy, and delete logged with the user and workstation, with alerts for bulk copying and after-hours access.
    • Three-year tamper-evident log retention off site, encrypted, with a monthly report the owners sign off on.
    • File server permissions rebuilt so employees can read and add, and only the owners can change or delete.
    • Application allow-listing rolled out in audit mode to control what software can run.
    • Acceptable use policy e-signed by all staff, with an annual re-sign.
    • Managed antivirus, patching, verified backups, and a monthly IT health report on every machine.

    Client name withheld at their request. References available for serious inquiries.

    Frequently asked questions

    We only have six people. Does this really apply to us?

    If you handle CUI under a DoD contract or subcontract, yes. Size does not exempt you. It does make you cheaper to fix.

    Can we just self-assess and post a score?

    For Level 1, yes. For Level 2 today, self-assessment is what is required, but the score has to be honest and a company officer affirms it. Posting 110 when you are at 40 is a legal problem, not a shortcut.

    What is CUI, exactly?

    Controlled Unclassified Information: unclassified data the government says must be protected. For a supplier that is usually drawings, specs, test reports, and anything marked CUI or flowed down from a program. If you are unsure what you have, that is the first thing we sort out.

    How long does readiness take?

    It depends on the starting point. A shop with a handful of machines and cooperative owners can be in good shape in a few months. Documents and evidence take as long as the technical work.

    What will it cost?

    We quote after the gap assessment, in writing, before any work starts. Our rates are well below regional compliance firms and there is no retainer.

    Do we need a separate “enclave” for CUI?

    Sometimes. Isolating the few machines that touch CUI can shrink what the assessor has to look at and cut cost. We will tell you if it makes sense for your shop.

    What about the Phase 2 suspension? Should we wait?

    The controls did not change and your contracts still require them. Waiting means doing the same work later, faster, under a deadline. Doing it now at your own pace is cheaper.

    Do you handle everything, or do we need other vendors?

    We handle the readiness work end to end. The assessment itself is done by an independent C3PAO, and for shops that need a certified provider to run part of their environment we bring in a Connecticut partner that holds Level 2 certification.

    Find out where you stand before your prime asks.

    Free on-site gap assessment with a written summary. No retainer, no long-term contract.

    CT Tech Express is an independent IT provider. We are not a C3PAO and do not issue CMMC certifications.